Show filters
26 Total Results
Displaying 11-20 of 26
Sort by:
Attacker Value
Unknown
CVE-2023-23721
Disclosure Date: March 20, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in David Gwyer Admin Log plugin <= 1.50 versions.
0
Attacker Value
Unknown
CVE-2017-20098
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
A vulnerability was found in Admin Custom Login Plugin 2.4.5.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to basic cross site scripting (Persistent). It is possible to launch the attack remotely.
0
Attacker Value
Unknown
CVE-2021-44096
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
EGavilan Media User-Registration-and-Login-System-With-Admin-Panel 1.0 is vulnerable to SQL Injection via profile_action - update_user. This allows a remote attacker to compromise Application SQL database.
0
Attacker Value
Unknown
CVE-2022-1589
Disclosure Date: May 30, 2022 (last updated February 23, 2025)
The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could also be performed via a CSRF vector
0
Attacker Value
Unknown
CVE-2021-24867
Disclosure Date: February 21, 2022 (last updated February 23, 2025)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
0
Attacker Value
Unknown
CVE-2021-24784
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin update them via a CSRF attack.
0
Attacker Value
Unknown
CVE-2020-23051
Disclosure Date: October 22, 2021 (last updated February 23, 2025)
Phpgurukul User Registration & User Management System v2.0 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the firstname and lastname parameters of the registration form & loginsystem input fields.
0
Attacker Value
Unknown
CVE-2021-34628
Disclosure Date: July 26, 2021 (last updated February 23, 2025)
The Admin Custom Login WordPress plugin is vulnerable to Cross-Site Request Forgery due to the loginbgSave action found in the ~/includes/Login-form-setting/Login-form-background.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.2.7.
0
Attacker Value
Unknown
CVE-2020-35263
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
EgavilanMedia User Registration & Login System 1.0 is affected by SQL injection to the admin panel, which may allow arbitrary code execution.
0
Attacker Value
Unknown
CVE-2020-29228
Disclosure Date: December 30, 2020 (last updated February 22, 2025)
EGavilanMedia User Registration and Login System With Admin Panel 1.0 is affected by SQL injection in the User Login Page.
0